{"id":"CVE-2018-11352","aliases":["GHSA-gvcw-x64m-pfcj"],"url":"https://o3.security/vulnerability/CVE-2018-11352","summary":"Wallabag cross-site scripting (XSS) vulnerability","details":"The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The vulnerability can be exploited with authentication and used to target administrators and steal their sessions.","published":"2018-09-21T16:29:00.297Z","modified":"2026-07-08T14:14:26.284521Z","cvss":{"score":4,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"wallabag/wallabag","fixedVersion":"2.3.3"}],"fix":null,"references":[{"type":"EVIDENCE","url":"https://www.bishopfox.com/news/2018/09/wallabag-2-2-3-to-2-3-2-stored-cross-site-scripting/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T14:14:26.284521Z"}}